GDPR & Security
Protecting the personal data of customers and candidates is one of our highest priorities.
Heyree is designed with a focus on security, privacy and GDPR compliance. It helps organisations securely manage recruitment processes and the personal data of candidates.
When using the platform, the customer acts as the controller of personal data and Heyree acts as the processor. We process personal data exclusively on behalf of the customer and in accordance with the customer's instructions.
1. Data security
We use technical and organisational measures designed to protect data against unauthorised access, loss or misuse.
Our security measures include:
- encrypted data transmission via HTTPS/TLS
- management of access rights and user roles
- protection of user accounts
- monitoring of infrastructure and system operations
- regular data backups
- restricted access to data for authorised persons only
Only persons who strictly need it for the provision and support of the service have access to customer data.
2. AI and data protection
The artificial intelligence features in Heyree are designed with a focus on privacy and data security.
Zero Retention: Data processed through AI services are not retained longer than necessary to process a specific request.
No Training: Neither customer nor candidate data are used to train public or shared AI models.
Data Minimization: Only the data necessary to complete a specific task are passed to AI features.
Your data always remain under your control.
3. Infrastructure and data storage
Heyree uses modern cloud infrastructure operated by trusted technology partners.
Primary customer data are stored in the European Union via AWS infrastructure in the EU-West-1 region (Dublin, Ireland).
We continuously evaluate our infrastructure and security architecture so that it meets high requirements for availability, performance and data protection.
4. Sub-processors
For the operation and provision of the service we use a limited number of trusted partners.
- Amazon Web Services (AWS)
- Cloud infrastructure and hosting
- Vercel
- Operation of the web application
- Convex
- Data layer and backend services
- Google Cloud Vertex AI
- AI features of the platform
- PostHog
- Product analytics
- Sentry
- Error and system reliability monitoring
- Postmark / SendGrid
- Delivery of system e-mails
5. International data transfers
If any of our providers processes a limited scope of data outside the European Union, we use appropriate safeguards in compliance with the GDPR.
These mechanisms may include:
- Standard Contractual Clauses (SCC)
- EU–US Data Privacy Framework (DPF)
- additional contractual and technical measures
We regularly assess the impact of international data transfers and the adequacy of the safeguards applied.
6. Data ownership
All data entered into the platform remain the property of the customer.
Heyree claims no ownership rights to customer data, candidate data or recruitment data stored in the system.
7. Data export and deletion
Customers can export their data throughout the entire period of using the service.
After the service ends, data are retained for a limited time for the purpose of export and migration, and are then securely deleted in accordance with the contractual documentation and applicable law.
8. Data Processing Agreement (DPA)
For our customers we provide a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.
The DPA governs the conditions for processing personal data between the customer as controller and Heyree as processor.
If you would like a copy of the DPA, please contact us.

